Score: 0.8 (>= 0.8) Infected Target: 192.168.1.154 Infector List: Egg Source List: C & C List: Peer Coord. List: Resource List: Observed Start: 06/20/2011 02:04:29.395 PDT Gen. Time: 06/20/2011 02:04:29.395 PDT INBOUND SCAN EXPLOIT EXPLOIT MALWARE DNS EGG DOWNLOAD C and C TRAFFIC C and C TRAFFIC (RBN) C and C DNS CHECK-IN OUTBOUND SKYPE CANDIDATE OUTBOUND SCAN (spp) OUTBOUND SCAN ATTACK PREP PEER COORDINATION DECLARE BOT 122.224.6.164 (02:04:29.395 PDT) event=1:9910005 {tcp} E8[rb] BotHunter REPO confirmed botnet control server, [] MAC_Src: 00:30:48:30:03:AF 1339->82 (02:04:29.395 PDT) tcpslice 1308560669.395 1308560669.396 inputFile.tcpd | tcpdump -r - -w outputFile.tcpd 'host 192.168.1.154' ============================== SEPARATOR ================================ Score: 2.2 (>= 0.8) Infected Target: 192.168.1.154 Infector List: Egg Source List: 122.224.6.164 C & C List: 140.174.25.8 (3), 64.38.232.180 Peer Coord. List: Resource List: Observed Start: 06/20/2011 02:04:29.395 PDT Gen. Time: 06/20/2011 02:07:15.501 PDT INBOUND SCAN EXPLOIT EXPLOIT MALWARE DNS EGG DOWNLOAD 122.224.6.164 (2) (02:04:29.792 PDT) event=1:2000419 {tcp} E3[rb] ET POLICY PE EXE or DLL Windows file download, [] MAC_Src: 00:21:1C:EE:14:00 1339<-82 (02:04:29.792 PDT) ------------------------- event=1:3300007 {tcp} E3[rb] BotHunter Malware Windows executable (PE) sent from remote host, [] MAC_Src: 00:21:1C:EE:14:00 1339<-82 (02:04:29.792 PDT) C and C TRAFFIC 140.174.25.8 (3) (02:04:49.773 PDT) event=1:2002196 (2) {tcp} E4[rb] ET MALWARE Casalemedia Spyware Reporting URL Visited 2, [/sd?s=84893&f=1] MAC_Src: 00:30:48:30:03:AF 1374->80 (02:04:49.773 PDT) 1374->80 (02:04:50.654 PDT) ------------------------- event=1:2009880 {tcp} E4[rb] ET MALWARE Casalemedia Spyware Reporting URL Visited 3, [/sd?s=84893&f=1&C=1] MAC_Src: 00:30:48:30:03:AF 1374->80 (02:04:50.654 PDT) C and C TRAFFIC (RBN) 64.38.232.180 (02:04:45.780 PDT) event=1:3810007 {tcp} E4[nbr] ET Known Russian Business Network Monitored Domain, [] MAC_Src: 00:30:48:30:03:AF 1349->80 (02:04:45.780 PDT) C and C DNS CHECK-IN OUTBOUND SKYPE CANDIDATE OUTBOUND SCAN (spp) OUTBOUND SCAN ATTACK PREP PEER COORDINATION DECLARE BOT 122.224.6.164 (02:04:29.395 PDT) event=1:9910005 {tcp} E8[rb] BotHunter REPO confirmed botnet control server, [] MAC_Src: 00:30:48:30:03:AF 1339->82 (02:04:29.395 PDT) tcpslice 1308560669.395 1308560669.396 inputFile.tcpd | tcpdump -r - -w outputFile.tcpd 'host 192.168.1.154' ============================== SEPARATOR ================================